Network Vulnerability in Linux Kernel Affects TCP Processing
CVE-2026-64007
Currently unrated
What is CVE-2026-64007?
A security issue in the Linux kernel's netfilter module arises from improper handling of TCP timestamps. The synproxy_tstamp_adjust function attempts to rewrite a TCP timestamp option but can lead to corrupt TCP checksum updates. When the skb_ensure_writable function is called, it may free the old skb->head and leave the pointer referencing stale memory. This can lead to either writing into freed slab memory or a mismatch between the packet's payload and its checksum, which could result in unintended network behavior or vulnerabilities in packet processing.
Affected Version(s)
Linux 48b1de4c110a7afa4b85862f6c75af817db26fad < 9902a1058992de5d95656b64a3bd95c077f7ba2c
Linux 48b1de4c110a7afa4b85862f6c75af817db26fad
Linux 48b1de4c110a7afa4b85862f6c75af817db26fad